Path traversal in starlette - CVE-2023-29159
Published: May 30, 2023
Vulnerability identifier: #VU76618
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-29159
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform directory traversal attacks.
The vulnerability exists due to input validation error when processing directory traversal sequences. A remote attacker can send a specially crafted HTTP request and read arbitrary files on the system.
Affected software
starlette
Debian Linux
starlette (Debian package)
IBM Cloud Pak for Watson AIOps
IBM Cloud Pak for Business Automation
IBM Business Automation Workflow
Debian Linux
starlette (Debian package)
IBM Cloud Pak for Watson AIOps
IBM Cloud Pak for Business Automation
IBM Business Automation Workflow
How to mitigate CVE-2023-29159
Install update from vendor's website.
starlette - update to 0.27.0
starlette (Debian package) - addressed in versions 0.26.1-1+deb12u1, 0.46.1-3+deb13u2
IBM Cloud Pak for Watson AIOps - update to 4.1.1
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.29, 23.0.2.1
IBM Business Automation Workflow - update to 23.0.2 IF001
starlette (Debian package) - addressed in versions 0.26.1-1+deb12u1, 0.46.1-3+deb13u2
IBM Cloud Pak for Watson AIOps - update to 4.1.1
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.29, 23.0.2.1
IBM Business Automation Workflow - update to 23.0.2 IF001